VDB
Sign up
HIGH7.8

GHSA-4whq-r978-2x68

Arbitrary code execution in ExifTool

Quick fix

GHSA-4whq-r978-2x68 — exiftool-vendored: upgrade to the fixed version with the command below.

npm install exiftool-vendored@14.3.0

Details

### Impact

Arbitrary code execution can occur when running `exiftool` against files with hostile metadata payloads.

### Patches

ExifTool has already been patched in version 12.24. exiftool-vendored, which vendors ExifTool, includes this patch in v14.3.0.

### Workarounds

No.

### References

https://twitter.com/wcbowling/status/1385803927321415687 https://nvd.nist.gov/vuln/detail/CVE-2021-22204

### For more information

If you have any questions or comments about this advisory: * Open an issue in [exiftool-vendored](https://github.com/photostructure/exiftool-vendored.js)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/exiftool-vendored
Introduced in: 0Fixed in: 14.3.0
Fixnpm install exiftool-vendored@14.3.0

References